How we handle your data.
Our customers run plants, pipelines, and other critical infrastructure, and they hold their own systems to a high bar. We hold the platform to the same one. The public posture is below: US data residency, no customer data in model training, SOC 2 Type II in progress, role-based access, and single sign-on (SSO) on Enterprise.
We share the sub-processor list and penetration-test letter under a non-disclosure agreement (NDA) on request. Our standard Data Processing Agreement (DPA) is being finalized, with an interim addendum available in the meantime.
- Residency
- US regions only
- Model training
- No customer data
- Encryption
- TLS 1.3 / AES-256
- SOC 2 Type II
- In progress, Q4 2026
The commitment schedule
Data residency
All customer data (queries, chats, LOI drafts, billing records) is stored in US-based regions, with US-based disaster recovery. No data leaves the United States. EU residency is available on Enterprise upon request.
No customer data used for model training
We never use your queries, chats, or uploaded content to train or fine-tune models, and our model providers do not train on data sent through their APIs. This is contractual.
Encryption
In transit: TLS 1.3 everywhere, HSTS enforced. At rest: AES-256 across the database, document store, and search index. Database backups encrypted with separate keys.
Access control
Role-based access (Owner / Admin / Member) at the org tenancy level, available on every plan. Enterprise tier adds single sign-on (SSO) via SAML 2.0 (Okta, Azure AD, Google Workspace). SCIM 2.0 user provisioning and workspace IP allow-listing are on the Enterprise roadmap. They are not yet generally available, so ask us about timelines if they gate your purchase.
Audit logging
We write account-level events to an append-only audit log: sign-in, member and role changes, organization and SSO provisioning, and billing actions. Each entry captures the target, a timestamp, and the acting user where the action carries one. Expanded coverage (chat access and Letter of Interpretation (LOI) export events, Admin-facing export, and SIEM streaming to Splunk, Datadog, and Elastic) is in active development for Enterprise. We will not represent it as shipped until it is. Talk to us if audit export is a requirement.
Sub-processors
Cairn relies on a small set of US-based sub-processors covering model inference, managed database, search infrastructure, object storage, and billing. The named list and notification policy are available on request. Our standard DPA is being finalized; an interim data-protection addendum is available for customers who need to sign before it ships.
Compliance
SOC 2 Type II audit in progress (Q4 2026). HIPAA BAA available on Enterprise. CJIS, FedRAMP, and ITAR not currently supported.
Vulnerability disclosure
We operate a private security disclosure program. Email security@cairnsafe.com with PGP-encrypted reports. We respond within one business day and run a 90-day disclosure timeline by default.
AI safety posture
Cairn is designed to refuse to fabricate. We ground assistant responses in retrieved citations or mark them as model-generated. We monitor citation hit rate, refusal rate, and prompt-injection attempts, and we review the findings weekly.
For a procurement review, see plans and pricing, who builds Cairn, or talk to sales about a security questionnaire.